Recently released NSA exploit from “The Shadow Brokers” leak that affects older versions of Cisco System firewalls can work against newer models as well.
Dubbed ExtraBacon, the exploit was restricted to versions 8.4.(4) and earlier versions of Cisco’s Adaptive Security Appliance (ASA) – a line of firewalls designed to protect corporate, government networks and data centers.
However, the exploit has now been expanded to 9.2.(4) after researchers from Hungary-based security consultancy SilentSignal were able to modify the code of ExtraBacon to make it work on a much newer version of Cisco’s ASA software.
Both Cisco and Fortinet have confirmed their firewalls are affected by exploits listed in the Shadow Brokers cache that contained a set of “cyber weapons” stolen from the Equation Group.
The Equation Group is an elite hacking group tied to the NSA’s offensive Tailored Access Operations (TAO) and linked to the previous infamous Regin and Stuxnet attacks.
As previously reported, the ExtraBacon exploit leveraged a zero-day vulnerability in the Simple Network Messaging Protocol (SNMP) code of Cisco’s ASA software that could allow “an unauthenticated, remote attacker to cause a reload of the affected system” and take full control of a firewall.
However, newly released exploit means that ExtraBacon poses a dangerous threat than previously thought, as the modified exploit now does not prevent it from running on newer versions of Cisco firewalls, allowing an attacker to execute malicious code remotely.
“We have test equipment and custom firmware images that make debugging easier,” Varga-Perke of SilentSignal told Ars. “These are most likely available for malicious parties, too; we are quite confident that similar code exists in private hands.”
Cisco engineers have provided workarounds that help ASA customers detect and stop ExtraBacon-powered attacks, though the multi-billion dollar company has yet to release software updates to address the flaw completely.
Just like researchers modified the exploit code to make it work on newer version of Cisco products, the hacking tools and exploits dumped by the Shadow Brokers could be exploited by a wide range of hackers to carry out advanced attacks.
By Mohit Kumar